Threats Tagged 'headlace'
View all threats tagged with 'headlace'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'headlace'
Click on any threat for detailed analysis and mitigation recommendations
Defense and Diplomacy Targeted with HOOKEDGE 0 Between late September 2025 and early April 2026, BlueDelta conducted espionage campaigns against government and diplomatic organizations in Romania, Spain, and Türkiye. The threat group deployed HOOKEDGE, a lightweight Windows batch-script backdoor, via macro-enabled Word documents using diplomatic-themed lures, including material impersonating Spain's Ministry of the Presidency created after a September 2025 meeting between Spanish and Moldovan officials. HOOKEDGE shares significant code and tradecraft overlap with the previously documented HEADLACE backdoor, abusing legitimate webhook services for command-and-control, payload staging, and data exfiltration. The implant underwent continuous refinement to evade sandbox environments and adapt to webhook service limitations. BlueDelta employed a tiered operational model, deploying second-stage payloads with shorter beaconing intervals for high-value targets while preserving initial-access infrastructure. Join the discussion | AlienVault OTX General | 08/27/2026, 17:37:41 UTC Added: 08/28/2026, 09:07:13 UTC |
Showing 1 to 1 of 1 result